|
256461
|
5.3 |
MEDIUM
Network
|
really
|
jwt-scala
|
jwt-scala 1.2.2 and earlier fails to verify token signatures correctly which may lead to an attacker being able to pass specially crafted JWT data as a correctly signed token.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2017-10862
|
2024-11-21 12:06 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256462
|
4.3 |
MEDIUM
Network
|
cybozu
|
office
|
Cybozu Office 10.0.0 to 10.6.1 allows authenticated attackers to bypass access restriction to perform arbitrary actions via "Cabinet" function.
|
CWE-269
Improper Privilege Management
|
CVE-2017-10857
|
2024-11-21 12:06 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256463
|
6.1 |
MEDIUM
Network
|
sap
|
enterprise_portal
|
Cross site scripting (XSS) vulnerability in SAP Enterprise Portal 7.50 allows remote attackers to inject arbitrary web script or HTML, aka SAP Security Notes 2469860, 2471209, and 2488516.
|
CWE-79
Cross-site Scripting
|
CVE-2017-10701
|
2024-11-21 12:06 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256464
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, an output buffer is accessed in one thread and can be potentially freed in another.
|
NVD-CWE-noinfo
|
CVE-2017-11041
|
2024-11-21 12:06 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256465
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, when reading from sysfs nodes, one can read more information than it is allowed to.
|
CWE-200
Information Exposure
|
CVE-2017-11040
|
2024-11-21 12:06 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256466
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing a vendor sub-command, a buffer over-read can occur.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11002
|
2024-11-21 12:06 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256467
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, the length of the MAC address is not checked which may cause out of bounds read.
|
CWE-200
Information Exposure
|
CVE-2017-11001
|
2024-11-21 12:06 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256468
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, in an ISP Camera kernel driver function, an incorrect bounds check may potentially lead to an out-of-bounds write.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11000
|
2024-11-21 12:06 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256469
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, concurrent calls into ioctl RMNET_IOCTL_ADD_MUX_CHANNEL in ipa wan driver may lead to memory corruption due to missing …
|
CWE-119 NVD-CWE-noinfo
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-10999
|
2024-11-21 12:06 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256470
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, in audio_aio_ion_lookup_vaddr, the buffer length, which is user input, ends up being used to validate if the buffer is …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-10998
|
2024-11-21 12:06 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|